Skip to content

Microsoft 365

Entra ID & Conditional Access

When the applications live in the cloud and staff work from anywhere, the network boundary stops being the thing protecting you. The identity is.

The problem

A password is one stolen credential away from the whole tenant

Most business email compromise starts with a working username and password — phished, bought, or reused from an unrelated breach. Without conditional controls that credential works from any country, on any device, at any hour, with nothing further asked. And permanent global administrator rights on an everyday account mean one compromised login is a compromised tenant.

Our approach

Conditions on every sign-in, and admin rights that expire

Conditional Access evaluates who is signing in, from where, on what device and how risky the attempt looks, then decides. Combined with phishing-resistant MFA and admin roles that are requested rather than held permanently, a stolen password stops being enough on its own.

What you get

Included as standard

Not an upsell list. These are the things that make the difference between a service you pay for and a service that works.

  • Conditional Access policies matched to how your people actually work
  • Phishing-resistant MFA where it matters most
  • Legacy authentication blocked outright
  • Device compliance required before company data is reachable
  • Sign-in risk and user risk acted on automatically
  • Just-in-time admin access instead of standing global admin
  • Guest and external collaboration governed rather than open
  • Break-glass accounts documented and stored properly

How we work

What actually happens

  1. 1

    Map

    Who needs what, from where, on which devices. Policy that ignores this produces workarounds.

  2. 2

    Design

    Policies written to fail safe, with break-glass accounts excluded and tested before enforcement.

  3. 3

    Pilot

    Report-only mode first, then a pilot group. You see the impact before anyone is locked out.

  4. 4

    Enforce

    Roll out in stages, watch the sign-in logs, adjust where real work meets friction.

Technologies

What we build on

Vendor-neutral where it matters. We will tell you when the cheaper option is the right one.

  • Microsoft Entra ID
  • Conditional Access
  • Entra ID Protection
  • Privileged Identity Management
  • Passkeys and FIDO2 security keys
  • Microsoft Authenticator

Questions

Entra ID questions

What is Conditional Access, in plain terms?

A set of if-then rules applied at sign-in. If a known person signs in on a managed, compliant laptop from Ocala, let them straight through. If the same account appears from another continent on an unrecognised device, require more proof or refuse. It is what lets you be strict without making everyday work irritating.

Could this lock us out of our own tenant?

It can if done carelessly, which is why break-glass accounts are created, excluded from the policies and tested before anything is enforced. Every policy also runs in report-only mode first, so you can see who it would have affected before it affects them.

Is text-message MFA good enough?

It is far better than nothing, and it is the weakest of the options. SMS codes can be intercepted or SIM-swapped, and both are used against small businesses. App-based approval is better; a passkey or hardware key is better again, and worth reserving at minimum for administrators and finance staff.

Ready to secure your business?

A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.

Call nowFree assessment